ITIL 5 PM : Collaborate, Assure and Improve - CAI (Domain 3)
ITIL 5 – Practice Manager : Certified ITIL Practice Manager - Domain 3 - Collaborate, Assure and Improve (CAI)
The release of ITIL Version 5 in early 2026 marks a decisive shift in the architecture of digital service delivery. Moving away from the traditional boundaries of IT Service Management (ITSM), the framework has transitioned into a holistic model known as Digital Product and Service Management (DPSM). This evolution addresses the modern realities of rapid delivery, AI-native operations, and the critical need for cross-practice collaboration. Within this new landscape, the Collaborate, Assure and Improve (CAI) domain stands as a vital pillar for professionals seeking the Practice Manager designation. It focuses on the strategic alignment of delivery capabilities with stakeholder expectations, third-party performance, and the continuous governance of risk and quality.
The Evolution of the ITIL 5 Operating Model
The architecture of ITIL 5 is built to dissolve the historical divide between software development and operational stability. Organizations no longer manage services in a vacuum; they orchestrate digital products through a unified lifecycle. This version of the framework decommissions the ITIL 4 classification of general, service, and technical management practices. Instead, all thirty-four practices are organized into two streamlined groupings: Product and Service Management Practices (22 practices) and General Management Practices (12 practices).
The CAI domain resides at the intersection of these groupings, ensuring that technical delivery is backed by robust general management capabilities such as relationship management and continuous learning. Central to this model is the concept of the Value System (formerly the Service Value System) and the Value Chain (formerly the Service Value Chain). By removing the word “Service” from these core terms, ITIL 5 acknowledges the total integration of digital products and services. The operating model is further enhanced by AI-native guidelines, including the AI Capability Model (6Cs), which provides a structured approach to categorizing AI functions: Creation, Curation, Clarification, Cognition, Communication, and Coordination.
The Practice Manager Designation and the CAI Pathway
To achieve the ITIL 5 Practice Manager credential, candidates must navigate a specific educational pathway designed to validate both strategic oversight and operational competence. The designation is intended for service desk managers, operational leaders, and consultants who must bridge the gap between individual practices and end-to-end value streams.
The qualification requirements are structured as follows:
- Foundational Baseline: Candidates must hold either the ITIL 5 Foundation certificate or use the ITIL 5 Foundation Bridge if they hold a legacy ITIL 4 Foundation certificate. The Bridge course is a specialized one-day update focusing on the transition to DPSM and AI integration.
- Specialized Practice Module: Candidates must complete one of the three-day pre-bundled practice modules. The CAI module is one such bundle, specifically targeting the governance and relationship-focused practices of the framework.
- The Transformation Corequisite: A mandatory component for all Practice Managers is the ITIL Transformation module. This capstone requirement replaces the legacy ITIL 4 Specialist: Create, Deliver and Support (CDS) requirement, reflecting a new emphasis on the Practice Manager as an active leader of organizational change rather than a maintainer of steady-state operations.
Strategic Architecture of the Collaborate, Assure and Improve Domain
The CAI domain is specifically engineered to address the complexities of modern, interconnected digital ecosystems. It brings together five core practices that, while distinct, operate as a functional cluster to ensure that the organization not only delivers what was promised but also continuously evolves to meet new market demands. The primary focus is on managing the human and contractual elements of service delivery, shifting metrics from simple technical uptime to experience-driven outcomes.
| Practice | Core Operational Focus |
|---|---|
| Relationship Management | Coordinating communication and value co-creation between providers and consumers. |
| Supplier Management | Governing third-party contracts and ensuring vendor performance aligns with business goals. |
| Service Level Management | Defining realistic targets and shifting from legacy SLAs to Experience-Level Agreements (XLAs). |
| Information Security Management | Implementing controls to protect digital assets and governing risk in an AI-native world. |
| Continual Improvement | Providing structured methods to systematically optimize processes and cultural mindsets. |
Relationship Management: Harmonizing Stakeholder Interests
Relationship Management in ITIL 5 is the practice of establishing and nurturing the links between the service provider and its stakeholders at both strategic and tactical levels. It is no longer enough to merely “manage” a customer; the goal is value co-creation. This practice ensures that the provider understands the business context of the consumer, while the consumer understands the capabilities and constraints of the provider.
Practice Success Factors (PSFs)
- Identification of Stakeholder Needs: The ability to move beyond stated requirements to understand the underlying business outcomes and emotional drivers of stakeholders.
- Facilitation of Communication: Creating consistent, transparent channels for feedback and strategic alignment.
- Expectation Management: Aligning the service catalog with what can realistically be delivered, preventing “expectation gaps” that lead to dissatisfaction.
Key Metrics
- Stakeholder Satisfaction Score (Net Promoter Score): Measuring the likelihood of stakeholders to recommend the provider.
- Communication Effectiveness: The frequency and quality of strategic reviews.
- Value Realization: Percentage of business outcomes achieved compared to initial stakeholder goals.
Supplier Management: Governing the Digital Ecosystem
Modern digital products are rarely built or operated by a single entity. Supplier Management governs the complex web of third-party vendors, cloud providers, and partners that contribute to the value chain. As organizations move toward AI-native operations, this practice becomes critical for managing algorithmic risks and ensuring that automated third-party services meet the organization’s ethical and performance standards.
Practice Success Factors (PSFs)
- Sourcing Strategy Alignment: Ensuring that the selection of vendors reflects the organization’s long-term digital strategy.
- Contractual Governance: Managing the lifecycle of agreements to ensure they remain flexible enough for modern delivery speeds.
- Performance Monitoring: Active oversight of vendor delivery against agreed-upon metrics.
Key Metrics
- Supplier Performance Against Targets: Percentage of vendors meeting or exceeding their contractual obligations.
- Contract Renewal Success Rate: The efficiency and timeliness of renegotiating vendor terms.
- Risk Mitigation Index: The number of third-party security or operational incidents identified and resolved.
Service Level Management: Transitioning to XLAs
The legacy approach to Service Level Management (SLM) often resulted in the “watermelon effect”—where technical metrics appeared “green” (healthy) while the actual user experience was “red” (failing). ITIL 5 addresses this by integrating Experience-Level Agreements (XLAs). SLM now focuses on the “warranty” of services—ensuring availability, capacity, and security—while prioritizing the digital experience (DX) of the end user.
Practice Success Factors (PSFs)
- Service Level Negotiation: Establishing realistic, measurable, and relevant targets that reflect business value rather than just technical uptime.
- Monitoring and Reporting: Developing telemetry that captures both system performance and user sentiment.
- Review and Improvement: Using service reviews as a platform for identifying improvement opportunities rather than just assigning blame for breaches.
Key Metrics
- XLA Achievement Rate: Percentage of experience-based targets met.
- SLA Breach Frequency: The number of times technical targets are missed.
- User Sentiment Index: Real-time feedback regarding the “feel” and usability of digital products.
Information Security Management: Governance in an AI-Native World
Information Security Management (ISM) ensures that the organization’s information assets are protected against unauthorized access, disclosure, and disruption. In the ITIL 5 framework, ISM is not a technical silo; it is a governance capability integrated into every stage of the product lifecycle. With the rise of AI, ISM must now account for the risks associated with automated decision-making and data curation within large language models.
Practice Success Factors (PSFs)
- Security Policy Alignment: Ensuring security controls do not hinder the speed of digital transformation while maintaining compliance.
- Risk Management: Proactively identifying threats to the “Value System” and implementing mitigation strategies.
- Incident Readiness: Ensuring the organization can detect, respond to, and recover from security breaches rapidly.
Key Metrics
- Mean Time to Detect (MTTD): The speed at which security threats are identified.
- Compliance Audit Success Rate: Percentage of internal and external audits passed without major non-conformities.
- Security Incident Volume: The number of verified breaches or data leaks.
Continual Improvement: Cultivating a Culture of Optimization
Continual Improvement is the practice of identifying and acting upon opportunities to improve services, products, and practices. It is the “connective tissue” of the CAI domain. ITIL 5 emphasizes that improvement is not a one-time project but a permanent organizational mindset. This practice utilizes various tools, including Value Stream Mapping (VSM) and Objectives and Key Results (OKRs), to ensure that optimization efforts are data-driven and aligned with strategic goals.
Practice Success Factors (PSFs)
- Improvement Opportunity Identification: Creating a culture where employees at all levels are encouraged to suggest enhancements.
- Resource Allocation for Improvement: Ensuring that “Improve” activities are funded and staffed, rather than being treated as “best effort.”
- Value Measurement: Validating that improvement initiatives actually resulted in the desired outcomes.
Key Metrics
- Improvement ROI: The financial or operational value generated by optimization projects.
- Participation Rate: The percentage of staff actively contributing to the improvement register.
- Velocity Increase: The measurable improvement in delivery speed post-optimization.
Integrating the ITIL Transformation Model into CAI
Because the Practice Manager is now viewed as a leader of change, the CAI domain must be understood through the lens of the ITIL Transformation Model. This model provides the architectural scaffolding for executing organizational shifts safely. It is built upon four functional layers:
- Governance Layer: Sets the strategic direction, ethical boundaries, and resource limits for improvement and relationship-building initiatives.
- Positioning Layer: Evaluates current capabilities and team readiness. In the CAI domain, this involves assessing the maturity of current relationships and supplier contracts.
- Execution Layer: Manages the actual rollout of changes. Practitioners must choose an Execution Pattern based on the environment’s complexity:
- Implement Pattern: Used in ordered, predictable environments.
- Discover Pattern: Applied in complex, unpredictable environments requiring iterative testing and feedback.
- Contain Pattern: Used in chaotic, high-risk situations to stabilize operations.
- Learning Layer: Captures feedback and integrates lessons learned back into the Value System, ensuring that the organization learns from every supplier interaction and service breach.
Managing the AI Capability Model (6Cs) within CAI
The integration of AI into the CAI practices requires a sophisticated understanding of the 6Cs model. Practice Managers must govern how AI is utilized across the Collaborate, Assure and Improve domain:
- Creation & Curation: AI can be used to generate initial service level targets or curate massive amounts of supplier data to identify performance trends.
- Clarification & Cognition: AI models can clarify complex security logs or provide cognitive insights into recurring relationship issues by analyzing sentiment in communication threads.
- Communication & Coordination: Automated systems can facilitate communication with users through intelligent service desks and coordinate the scheduling of improvement activities across global teams.
Operational Constraints and the Theory of Constraints (ToC)
Within the CAI domain, the Practice Manager must use the Theory of Constraints (ToC) to identify bottlenecks in the Value System. For example, a “Relationship Management” practice might be performing excellently, but if the “Supplier Management” process is slow to authorize new vendors, the end-to-end value stream remains stalled. Practitioners are encouraged to use Value Stream Mapping (VSM) to visualize these workflows and apply the RACI (Responsible, Accountable, Consulted, Informed) matrix to clarify accountabilities, especially when automated AI systems are involved in decision-making.
Examination Specifications for the CAI Specialist Module
Preparation for the CAI specialist exam requires a shift in focus from rote memorization to analytical application. The exam evaluates a candidate’s ability to coordinate these five practices in complex scenarios.
| Component | Specification |
|---|---|
| Format | Multiple-choice, closed-book. |
| Question Count | 60 Questions. |
| Time Limit | 90 Minutes (plus 25% for non-native speakers). |
| Passing Score | $\ge 65%$ (39 out of 60 correct answers). |
| Reference Materials | None permitted during the exam. |
Successful candidates should prioritize the relationship between practices. For example, how a change in “Service Level Management” (shifting to XLAs) directly impacts “Supplier Management” (requiring new vendor contract terms).
Summary of Practice Manager Renewal and Growth
Once achieved, the Practice Manager designation is valid for three years. Professionals have three primary routes for renewal:
- Professional Development: Logging 20 CPD (Continuous Professional Development) points annually on the PeopleCert Plus portal.
- Further Examination: Passing another specialist module or moving toward the Managing Professional (MP) or Strategic Leader (SL) designations.
- Retesting: Retaking the current examination to demonstrate continued competence in the evolved framework.
The CAI domain provides the essential governance and human-centric skills needed to lead in a digital-first economy. By mastering the balance between supplier coordination, experience-driven metrics, and continuous security, Practice Managers ensure that technology serves as a true catalyst for business value.
Short-Answer Questions
1. What is the primary difference between the legacy ITIL 4 Service Value System and the ITIL 5 Value System? The word “Service” has been removed to reflect the complete integration of digital products and services into a single unified management model.
2. In the context of ITIL 5, what does the ‘Discover’ Execution Pattern entail? It is applied in complex, unpredictable environments where outcomes are uncertain, requiring iterative experimentation, testing, and continuous feedback loops to guide change.
3. How does the AI Capability Model classify ‘Cognition’? Cognition refers to the AI’s ability to process complex data sets to provide insights, recognize patterns, and support human decision-making within the Value System.
4. What is the mandatory corequisite for the ITIL 5 Practice Manager designation? The ITIL Transformation (Version 5) module is the universal and mandatory corequisite for the Practice Manager, Managing Professional, and Strategic Leader paths.
5. Define the ‘Watermelon Effect’ in Service Level Management. It describes a situation where technical SLAs appear “green” (met), but the actual user experience is “red” (poor), highlighting a disconnect between metrics and reality.
6. What are the eight activities of the unified Product and Service Lifecycle Model? The activities are Discover, Design, Acquire, Build, Transition, Operate, Deliver, and Support.
7. Why was ‘Design and Transition’ split into two separate activities in ITIL 5? The split allows organizations to manage transition and release as automated, continuous integration workflows while maintaining a dedicated focus on human-centric, experience-driven design.
8. What tool is recommended for identifying process bottlenecks and optimizing work flow? Value Stream Mapping (VSM) is the primary technique used to visualize operational workflows and identify areas of waste or delay.
9. In Information Security Management, what does ‘Mean Time to Detect’ (MTTD) measure? MTTD measures the average time it takes for the organization to identify a potential security threat or breach after it has occurred.
10. What is the purpose of the ‘Contain’ Execution Pattern? It is used in chaotic or high-risk situations to provide immediate stabilization of a failure before attempting systematic, long-term organizational change.
Answer Key
- Answer: The removal of “Service” signifies that digital products and services are no longer managed separately. It reflects a shift toward Digital Product and Service Management (DPSM).
- Answer: The Discover pattern focuses on iterative experimentation. It is used when the results of a change cannot be predicted in advance due to system complexity.
- Answer: Cognition involves the analysis of information to derive deeper understanding. It helps practitioners move from raw data to actionable intelligence within management practices.
- Answer: The ITIL Transformation module is the mandatory requirement. It ensures Practice Managers can lead organizational change and manage the complexities of digital transformation.
- Answer: It refers to misleading metrics that hide poor user experiences. Shifting to XLAs (Experience-Level Agreements) is the primary method used to solve this issue.
- Answer: The eight activities are Discover, Design, Acquire, Build, Transition, Operate, Deliver, and Support. These replace the legacy Value Chain activities to support modern rapid delivery.
- Answer: To support high-velocity delivery. Transition can be highly automated (DevOps), whereas Design requires a focus on stakeholder experience and human factors.
- Answer: Value Stream Mapping (VSM). This technique allows teams to see the end-to-end flow of value and target specific improvements.
- Answer: The speed of threat identification. A lower MTTD indicates a more mature and responsive security practice.
- Answer: Immediate stabilization of chaotic events. This pattern prevents further damage in a crisis so that more permanent solutions can be planned later.
Design and Open-Ended Questions
-
Architectural Coordination: A global enterprise is moving to a multi-cloud environment using ten different vendors. Design a Supplier Management strategy that uses AI-driven “Cognition” to monitor contractual compliance across these vendors while ensuring the “Relationship Management” practice remains the primary point of contact for internal business units. How do you prevent the communication from becoming fragmented?
-
XLA Implementation: An organization has consistently met its 99.9% availability SLAs for five years, yet employee satisfaction surveys show a 40% dissatisfaction rate with the digital workplace. Outline a plan to implement Experience-Level Agreements (XLAs) that incorporate the “Learning Layer” of the Transformation Model. What specific experience metrics would you introduce, and how would you link them to the “Continual Improvement” practice?
-
Security Governance in AI: You are the Practice Manager for an organization that has recently deployed an AI-native customer service bot. The bot curation process is automated. Using the “Information Security Management” practice and the “Governance Layer” of the Transformation Model, design a risk framework to manage the threat of the bot providing biased or insecure information to customers. Who is “Accountable” in your RACI matrix when the AI makes an autonomous decision that results in a security breach?
-
Cultural Barriers to Improvement: A legacy IT department is resistant to the move from ITSM to DPSM, viewing “Continual Improvement” as an unnecessary overhead that slows down their “Build” activities. Using the “Initiation Patterns” of the Transformation Model, design a strategy to overcome this cultural barrier. Which execution pattern (Implement, Discover, or Contain) would you choose to start this cultural shift, and why?
-
Supplier Coordination & Conflict: During a major system transition, a conflict arises between a primary software vendor and an internal deployment team, causing a bottleneck in the “Value Chain.” As a Practice Manager, apply the “Theory of Constraints” and the “Relationship Management” practice to resolve this conflict. How would you redefine the “Service Level Management” targets to ensure both parties are incentivized to cooperate toward a shared business outcome?
Glossary of Key CAI Terms
- AI Capability Model (6Cs): A functional classification system in ITIL 5 used to categorize AI roles: Creation, Curation, Clarification, Cognition, Communication, and Coordination.
- AI-Native Operational Model: An environment where artificial intelligence and automation are integrated into the core architecture of service delivery and decision-making.
- Collaborate, Assure and Improve (CAI): A specialist practice bundle focused on relationship management, supplier governance, service levels, security, and optimization.
- Continual Improvement: The practice of systematically identifying and acting upon opportunities to optimize products, services, and management practices.
- Digital Experience (DX): The total sum of perceptions and feelings resulting from a user’s interaction with an organization’s digital products and services.
- Digital Product and Service Management (DPSM): The holistic model in ITIL 5 that replaces traditional IT Service Management to unify product development and service operations.
- Execution Patterns: Strategic approaches (Implement, Discover, Contain) used within the ITIL Transformation Model to navigate different levels of environmental complexity.
- Experience-Level Agreement (XLA): An agreement between a service provider and a customer that prioritizes human-centric outcomes and perceptions over technical metrics.
- Information Security Management: The practice of protecting the information an organization needs to conduct its business by managing risks to confidentiality, integrity, and availability.
- ITIL Transformation Model: A functional framework consisting of four layers (Governance, Positioning, Execution, Learning) used to manage organizational change.
- Practice Success Factor (PSF): A complex functional component of a practice that is required for the practice to fulfill its intended purpose.
- Relationship Management: The practice of establishing and nurturing links between an organization and its stakeholders to ensure value co-creation.
- Service Level Management: The practice of setting clear, business-based targets for service performance and delivery against those targets.
- Supplier Management: The practice of ensuring that an organization’s suppliers and their performance are managed appropriately to support the seamless delivery of products and services.
- Theory of Constraints (ToC): A methodology for identifying the most important limiting factor (bottleneck) that stands in the way of achieving a goal and then systematically improving that constraint.
- Value Chain: The set of interconnected activities (Discover, Design, Acquire, Build, Transition, Operate, Deliver, Support) used to create a product or service.
- Value Stream Mapping (VSM): A lean management tool used to visualize the flow of materials and information required to bring a product or service to a consumer.
- Value System: The high-level model representing how all components and activities of an organization work together as a system to facilitate value creation.
Leaderboard
No scores saved yet. Be the first!
30 Questions — ITIL 5 – Practice Manager : Certified ITIL Practice Manager - Domain 3 - Collaborate, Assure and Improve (CAI)
Expand any question to reveal the correct answer and explanation.
-
1 An organization is transitioning from rigid uptime SLAs to experience-driven XLAs. During a quarterly review, a primary vendor meets the $99.99\%$ availability target, but user sentiment scores have plummeted due to intermittent high latency. Which action best reflects the integrated application of Service Level Management (SLM) and Relationship Management?
Focus on the shift from technical outputs to human-centric outcomes through collaboration.
Facilitate a joint workshop with the vendor and business stakeholders to redefine performance metrics around user journey completion times.
This approach uses Relationship Management to align stakeholders and SLM to evolve metrics from technical outputs to meaningful outcomes.
-
✗ Immediately enforce financial penalties based on the breach of the existing availability SLA to signal dissatisfaction.
Enforcing penalties for a target that was technically met ignores the shift toward experience and may damage the trust needed for co-creation.
-
✗ Task the Supplier Management team with sourcing a new vendor who can guarantee lower latency in the baseline contract.
Sourcing a new vendor is a premature operational move that bypasses the need for relationship-driven improvement and requirement clarification.
-
✗ Instruct Information Security Management to audit the vendor's infrastructure to determine if a security event caused the latency.
While security audits are important, this treats a performance/experience issue as a purely technical security failure without addressing the underlying value gap.
-
-
2 A massive data leak is traced back to an unpatched vulnerability in a third-party partner's environment. While the contract has a generic 'security compliance' clause, it lacks specific remediation timelines. How should the Collaborate, Assure and Improve (CAI) practices be coordinated to mitigate future risk?
Consider the link between technical security standards and the formal agreements that govern external partners.
Information Security Management defines the technical requirements, while Supplier Management renegotiates the contract to include specific security-focused Practice Success Factors (PSFs).
This leverages InfoSec for technical standards and Supplier Management for the formal governance and enforcement mechanism.
-
✗ Continual Improvement initiates a value stream mapping exercise to find bottlenecks in the partner's internal patching process.
Directly managing a third party's internal processes is typically outside the scope of a standard service provider relationship.
-
✗ Relationship Management issues a formal apology to users and SLM lowers the service availability target to account for future breaches.
Lowering targets accepts failure rather than improving assurance, and an apology does not address the underlying contract or security gaps.
-
✗ Supplier Management terminates the contract immediately based on the 'ethical impact' clause within the ITIL 5 sustainability guidelines.
Immediate termination without a transition plan often causes more operational risk than the initial breach, violating the principle of holistic thinking.
-
-
3 In the context of the ITIL Capability Model for the CAI bundle, an organization finds that its 'Supplier Management' practice is at a maturity level where it effectively manages contracts but fails to leverage vendor innovation. What is the most logical next step to develop this capability?
Think about how to move from a transactional mindset to a strategic partnership mindset.
Apply Relationship Management principles to establish 'innovation forums' where partners contribute to the product roadmap.
Moving from transactional management to strategic partnership is a core objective of evolving the capability of the Supplier Management practice.
-
✗ Increase the frequency of automated performance reports generated by the SLM tools.
More reporting on existing metrics reinforces the current state rather than evolving the practice toward collaborative innovation.
-
✗ Centralize all supplier interactions under the Information Security Management practice to ensure compliance is prioritized over speed.
Prioritizing security over innovation creates a siloed approach that ignores the need for business agility and value co-creation.
-
✗ Reduce the number of suppliers to a single primary vendor to simplify communication channels and reduce complexity.
Reducing vendors may simplify management but it also increases risk and reduces the organization's access to diverse market innovations.
-
-
4 A service provider is using AI to automate the filtering of security events. However, the AI model has begun flagging legitimate stakeholder communication from Relationship Management as 'phishing.' Which practice should lead the corrective action and what technique should be used?
Look for the specific ITIL 5 model designed for managing the functions and roles of AI solutions.
Information Security Management should apply the ITIL 5 'AI Capability Model' to clarify and retrain the cognition and communication functions of the model.
InfoSec owns the security tool, and the 6Cs model is specifically designed to classify and improve AI functions within ITIL 5.
-
✗ Continual Improvement should use Value Stream Mapping (VSM) to remove the AI tool from the workflow entirely.
Removing the tool is a reactive measure that ignores the goal of optimizing and automating work through AI.
-
✗ Supplier Management should dispute the contract with the AI vendor for providing a defective product that violates the warranty.
Disputing the contract is a tactical legal move that does not address the immediate need for internal process alignment and AI governance.
-
✗ SLM should update the SLA to exclude phishing detection as a performance metric until the tool is fixed.
Changing the SLA to hide a failure prevents the organization from addressing the root cause and reduces transparency with the consumer.
-
-
5 A company is integrating multiple Agile development teams with a legacy operations group. The teams often disagree on the 'Definition of Done' regarding security documentation. Which CAI practice acts as the primary 'Assurance' mechanism in this scenario?
Assurance is about ensuring that requirements, specifically those related to risk and compliance, are consistently met.
Information Security Management, by defining and validating the security criteria that must be met before a product enters the 'Operate' stage.
InfoSec provides the specific governance and controls that assure the product is safe and compliant, regardless of the delivery velocity.
-
✗ Relationship Management, by managing the conflict between the development and operations leads.
Relationship Management facilitates the connection but does not provide the objective assurance standards for the product itself.
-
✗ Continual Improvement, by ensuring the team reviews their mistakes in a post-implementation review (PIR).
Continual Improvement looks backward to learn, whereas the question asks for the mechanism that provides assurance during the lifecycle integration.
-
✗ Service Level Management, by tracking how long it takes to complete the security documentation.
Tracking duration measures efficiency (speed) but does not provide assurance regarding the quality or effectiveness of the security controls.
-
-
6 While applying the ITIL Transformation Model to a CAI-focused initiative, a manager identifies that the environment is 'Complex' because the outcomes of a new multi-vendor governance model are unpredictable. Which Execution Pattern should be deployed?
Match the pattern to the complexity level characterized by unpredictable outcomes and the need for feedback loops.
The Discover Pattern, using iterative experimentation and continuous feedback to navigate the uncertainty.
The Discover Pattern is explicitly designed for complex environments where outcomes are unpredictable and require testing.
-
✗ The Implement Pattern, focusing on a structured, sequential rollout based on best practices.
The Implement Pattern is for 'Ordered' environments where the path is clear, not complex ones with high uncertainty.
-
✗ The Contain Pattern, to stabilize the multi-vendor environment before attempting any changes.
The Contain Pattern is for 'Chaotic' or high-risk failure situations, not for standard complex transformation initiatives.
-
✗ The Optimize Pattern, to focus on removing waste from the existing vendor management processes.
The 'Optimize Pattern' is not one of the three primary Execution Patterns defined in the ITIL 5 Transformation curriculum.
-
-
7 An organization discovers 'Value Leakage' occurring because business units are bypassing the standard procurement process to hire niche AI consultants. Which CAI practice interaction is most critical to resolve this while maintaining business agility?
Consider the tension between the need for fast access to expertise and the need for controlled, cost-effective governance.
Supplier Management and Relationship Management.
Relationship Management understands the business need for speed, while Supplier Management ensures the new partners are governed and leveraged effectively.
-
✗ Information Security Management and Continual Improvement.
While security is a concern, 'value leakage' is primarily a governance and relationship issue regarding how services are acquired and managed.
-
✗ Service Level Management and Supplier Management.
SLM focuses on performance targets once a service exists; it does not solve the root issue of shadow IT procurement.
-
✗ Continual Improvement and SLM.
This combination focuses on optimizing existing services rather than fixing the strategic misalignment in the acquisition process.
-
-
8 A key Practice Success Factor (PSF) for the 'Collaborate, Assure and Improve' bundle is the 'Integration of practices in the organization's value streams.' How does the ITIL 5 Product and Service Lifecycle support this specifically?
Look for a structural change in the lifecycle activities that allows for simultaneous focus on human experience and technical speed.
By splitting the legacy 'Design and Transition' activity into two, allowing for dedicated focus on experience-driven design and automated transition.
This split allows practices like SLM to focus on design/experience, while InfoSec and Supplier Management focus on the automation and assurance of the transition.
-
✗ By requiring all 34 practices to be active at every stage of the lifecycle.
Not all practices are needed at every stage; they are applied selectively based on the value stream's specific requirements.
-
✗ By replacing the Service Value System with a linear chain of eight sequential steps.
The lifecycle is an interconnected model, not a linear chain, and it complements rather than replaces the Value System.
-
✗ By decommissioning the 'General Management Practices' category to simplify the execution layer.
General management practices were not decommissioned; they were reorganized but remain essential to the framework's architecture.
-
-
9 A Service Level Manager is tasked with creating a new dashboard. The business wants to see the correlation between third-party cloud costs and customer satisfaction scores. Which three practices must collaborate to produce this insight?
Identify the practices that own the specific data points: customer sentiment, vendor financials, and performance targets.
Relationship Management, Supplier Management, and Service Level Management.
Relationship Management provides the satisfaction data, Supplier Management provides the vendor cost data, and SLM integrates them into a target-based view.
-
✗ Continual Improvement, Information Security Management, and Relationship Management.
Security data is not required for a cost/satisfaction correlation, making this combination less relevant to the specific business request.
-
✗ Supplier Management, Information Security Management, and SLM.
The customer satisfaction component (Relationship Management) is missing from this group, leaving the dashboard incomplete.
-
✗ Information Security Management, Continual Improvement, and Supplier Management.
This group lacks both the customer interface (RM) and the performance target framework (SLM) required for the dashboard.
-
-
10 A major vendor dispute arises when a service provider claims that a security breach was caused by 'shadow IT' devices introduced by the client, while the client claims the vendor's Monitoring practice failed to alert them. Which tool should be used first to clarify accountability?
Think of a standard management tool used specifically to define who is Responsible, Accountable, Consulted, and Informed.
A RACI or RASCI matrix.
The ITIL 5 curriculum explicitly recommends RACI/RASCI matrices to clarify team accountabilities, especially in complex multi-stakeholder environments.
-
✗ A Value Stream Map (VSM).
VSM identifies flow and bottlenecks but is not the primary tool for defining individual or organizational accountability.
-
✗ A Sustainability Audit.
Sustainability audits focus on long-term ethical and environmental impact, not on clarifying immediate operational accountabilities for a breach.
-
✗ An OKR (Objectives and Key Results) framework.
OKRs measure outcomes and success; they do not define the specific roles and responsibilities required to resolve a dispute.
-
-
11 Information Security Management in ITIL 5 is increasingly focused on 'Algorithmic Risk.' What does this mean for the Collaborate, Assure and Improve bundle?
Consider how the framework adapts to a world where technology makes significant operational decisions.
Assurance must now include the governance of decisions made by automated models and AI, not just human actors.
As AI is integrated into the Value System, assigning accountability for algorithmic decisions becomes a core part of the Assurance function.
-
✗ Collaboration must be restricted to prevent AI models from learning sensitive organizational secrets.
Restriction prevents value co-creation; the framework focuses on *governed* adoption rather than blocking collaboration.
-
✗ Continual Improvement must be performed by AI to ensure that algorithms are optimized without human bias.
Human-centric design is a pillar of ITIL 5; the framework emphasizes human oversight rather than total AI autonomy in improvement.
-
✗ Supplier Management should only hire vendors who do not use algorithms to deliver their services.
This is practically impossible in the modern digital landscape and contradicts the framework's 'AI-native' design.
-
-
12 An organization is at the 'Positioning Layer' of an ITIL Transformation. They are evaluating their current multi-vendor relationships before moving to a new cloud-native model. Which CAI-related activity is most appropriate at this stage?
Think about the layer of the Transformation Model that focuses on situational analysis and setting the baseline.
Conducting a readiness assessment to evaluate the current maturity of Supplier Management and Relationship Management practices.
The Positioning Layer is about analyzing baselines, evaluating readiness, and setting direction before executing change.
-
✗ Renegotiating all existing contracts to include cloud-specific terms.
Renegotiation happens at the 'Execution Layer' once the strategy and baselines have been established.
-
✗ Implementing a new automated monitoring tool to replace the legacy vendor's system.
Tool implementation is part of the Execution Layer, which follows the strategic positioning and analysis phase.
-
✗ Capturing feedback from the transformation to improve the next iteration of the Value System.
Feedback capture and learning occur at the 'Learning Layer,' which is the final layer of the Transformation Model.
-
-
13 A Relationship Manager identifies that a customer's 'Digital Experience (DX)' is being degraded by complex security authentication steps. Which practice conflict does this illustrate, and how should it be resolved according to the CAI guidance?
The goal is to co-create value by balancing security necessity with user experience fluidity.
Relationship Management vs. Information Security Management; resolved by redesigning the security controls to be 'transparent' or less intrusive using modern technologies.
ITIL 5 emphasizes experience-driven design, requiring security to be integrated in a way that minimizes friction for the user.
-
✗ Relationship Management vs. Information Security Management; resolved by prioritizing user experience over security to ensure high satisfaction.
Prioritizing satisfaction over security creates unacceptable business risk; the goal is alignment, not the abandonment of controls.
-
✗ SLM vs. Continual Improvement; resolved by removing the SLM targets for authentication speed.
The conflict is between the need for security (InfoSec) and the desired experience (RM), not between performance and improvement practices.
-
✗ Supplier Management vs. SLM; resolved by penalizing the security vendor for the slow authentication speeds.
Penalizing a vendor does not solve the design conflict between experience requirements and security controls.
-
-
14 Which specific 'Initiation Pattern' in the ITIL Transformation curriculum applies when a new government regulation requires all third-party vendors to meet a specific information security standard within six months?
Focus on the trigger that is external, non-negotiable, and focused on compliance standards.
Mandatory Regulatory, Compliance, or Legal Requirement Pattern.
This pattern is characterized by non-negotiable scopes and timelines driven by government or compliance standards.
-
✗ Market Demand Pattern.
Market Demand is driven by customers or competitors, not by non-negotiable legal or regulatory mandates.
-
✗ Structural Business Change Pattern.
Structural change relates to mergers, acquisitions, or internal reorganizations, not external regulatory compliance.
-
✗ Internal Improvement or Remediation Pattern.
This pattern focuses on optimizing internal throughput or reducing waste, not reacting to external legal mandates.
-
-
15 Service Level Management in ITIL 5 introduces the concept of 'Sustainability targets.' How does this interact with Supplier Management in a CAI-aligned value stream?
Consider how high-level ethical goals are translated into operational agreements with external partners.
SLM defines sustainability metrics (e.g., carbon footprint of data centers), and Supplier Management embeds these into vendor contracts and performance reviews.
This ensures that the organization's sustainability goals are consistently applied and assured through third-party partnerships.
-
✗ Suppliers are only required to meet financial targets; sustainability is an internal IT goal.
Sustainability is embedded across the framework and includes the entire supply chain, not just internal operations.
-
✗ Supplier Management must terminate any vendor who does not have an ISO 14001 certification.
ITIL 5 is flexible and focuses on improvement; it provides guidance to work with vendors toward goals rather than using rigid disqualifiers.
-
✗ Continual Improvement replaces SLM in managing sustainability because it is a long-term goal.
Continual Improvement supports the optimization, but SLM is the practice responsible for defining and monitoring the specific targets.
-
-
16 A Practice Manager is evaluating the 'Monitor, Support and Fulfil (MSF)' bundle but finds they need to improve the relationship between the Service Desk and external software vendors. Which CAI practice should they borrow concepts from, and which PSF is most relevant?
The issue involves communication, trust, and the interface between internal teams and external providers.
Relationship Management; focusing on the PSF 'Establishing and maintaining healthy relationships with stakeholders.'
Improving the link between the internal desk and external providers is a core function of Relationship Management.
-
✗ Information Security Management; focusing on the PSF 'Protecting the organization's information assets.'
While security is important, it does not directly address the communication and collaboration gap between a desk and a vendor.
-
✗ Continual Improvement; focusing on the PSF 'Developing and maintaining a culture of improvement.'
Cultural improvement is a broad outcome, but the specific need for better vendor-desk collaboration is a Relationship/Supplier issue.
-
✗ SLM; focusing on the PSF 'Defining and agreeing on service targets.'
Targets measure the result, but they do not manage the day-to-day relationship and collaboration needed to fix the underlying communication gap.
-
-
17 What is the passing requirement for the ITIL 5 'Collaborate, Assure and Improve' specialized module, and what is its format?
Consider the standard question count and pass mark for advanced specialized practice bundles.
$\ge 65\%$ (39 out of 60); Closed-book multiple choice.
The specialized practice modules (MSF, PIC, CAI) consist of 60 questions with a $65\%$ passing score and are closed-book.
-
✗ $\ge 65\%$ (26 out of 40); Closed-book multiple choice.
This describes the Foundation exam requirement, not the specialized practice module requirement.
-
✗ $\ge 70\%$ (28 out of 40); Open-book based on scenario booklets.
This describes the Transformation module requirement, which is the only one in the Practice Manager path that is open-book.
-
✗ $\ge 65\%$ (13 out of 20); Closed-book multiple choice.
This describes the Foundation Bridge exam requirement, which is much shorter than the full practice modules.
-
-
18 During a value stream mapping exercise for the CAI bundle, the team discovers that 'Information Security Management' reviews are causing a three-week delay in the 'Transition' stage. How should 'Complexity Thinking' be applied here?
Identify a strategy that balances the need for security assurance with the goal of high-velocity delivery in a modern environment.
Acknowledge the 'Complex' context and use the 'Discover' pattern to experiment with 'Shift-Left' security automation to reduce manual reviews.
This recognizes that the solution isn't straightforward and requires iterative testing (shifting security earlier) to balance speed and assurance.
-
✗ Treat the situation as 'Ordered' and implement a rigid, faster schedule for security reviews.
If a process is causing significant delays in a complex environment, simply demanding more speed without understanding the context usually increases risk.
-
✗ Classify the environment as 'Chaotic' and trigger the 'Contain' pattern to halt all transitions until security is fixed.
A three-week delay is an operational bottleneck, not a chaotic system failure requiring a complete shutdown.
-
✗ Apply the 'Implement' pattern to ensure that the existing manual security steps are followed more strictly.
Strictly following the existing failing process (which causes the delay) does not solve the bottleneck or leverage modern ways of working.
-
-
19 How does the 'Learning Layer' of the ITIL Transformation Model specifically enhance the 'Continual Improvement' practice within the CAI bundle?
Think about the layer that focuses on post-implementation feedback and long-term evolutionary growth.
By capturing post-implementation feedback and signals of change to refine the organization's Service Value System.
The Learning Layer focuses on evaluating results and integrating lessons back into the operational engine to sustain long-term success.
-
✗ By providing the budget needed to hire external improvement consultants.
Budget and resource allocation are primarily functions of the 'Governance Layer,' not the Learning Layer.
-
✗ By establishing the initial baseline for current operational readiness.
Setting the baseline is a function of the 'Positioning Layer,' which precedes the Learning Layer.
-
✗ By deploying the new changes across people, processes, products, and tools.
Deployment and governance of change during the initiative are functions of the 'Execution Layer.'
-
-
20 A Relationship Manager is dealing with a high-power, low-interest stakeholder who is unhappy with the performance of a new digital product. Which tactic is best supported by the CAI practices?
Consider how to align communication and reporting with the power/interest profile of a key stakeholder.
Use SLM to provide the stakeholder with simplified, high-level reports focused on value-driven OKRs rather than technical KPIs.
This aligns communication to the stakeholder's level (high-power, low-interest) while using SLM to focus on the outcomes they care about.
-
✗ Request Supplier Management to change the vendor responsible for the product's UI design.
Changing vendors is a major action that should follow a failure in governance, not a single stakeholder's dissatisfaction.
-
✗ Ignore the stakeholder since they are 'low-interest' and focus only on users with high interest scores.
High-power stakeholders can derail initiatives if their needs aren't addressed; they must be kept satisfied through appropriate communication.
-
✗ Instruct InfoSec to restrict the stakeholder's access to detailed performance data to prevent further complaints.
Restricting data to hide failure is unethical and violates the ITIL principle of 'collaborate and promote visibility.'
-
-
21 An organization is applying 'Value Stream Mapping' (VSM) to its CAI processes and identifies that the 'Supplier Management' practice is a significant bottleneck. What is the most common reason for this in the ITIL 5 context?
Think about why modern, high-velocity environments find legacy management processes frustrating.
Manual handoffs and rigid, sequential approval cycles for vendor activities that could be automated.
ITIL 5 identifies manual, non-flow-based processes as a key source of waste in modern digital product management.
-
✗ Lack of AI tools to write vendor contracts.
Contracts require human ethical and legal judgment; the absence of AI for writing them is rarely a primary bottleneck.
-
✗ The decommissioning of the 'Service Value Chain' which previously managed these handoffs.
The Service Value Chain evolved into the Lifecycle Model; it was not decommissioned in a way that would cause operational bottlenecks.
-
✗ A lack of 'General Management Practices' in the Supplier Management grouping.
Supplier Management is itself a practice; its effectiveness is not determined by its presence in a specific categorical grouping.
-
-
22 A Practice Manager needs to achieve the 'ITIL Master' designation. Based on the ITIL 5 scheme, what is the mandatory sequence of advanced modules they must complete?
Mastery in ITIL 5 is the culmination of three distinct advanced designations.
Foundation -> Practice Manager -> Managing Professional -> Strategic Leader.
Achieving ITIL Master requires completing all three intermediate pathways: Practice Manager, Managing Professional, and Strategic Leader.
-
✗ Foundation -> Transformation -> AI Governance -> Master.
Transformation and AI Governance are modules within the pathways, not a sequence that bypasses the three primary designations.
-
✗ Practice Manager (MSF, PIC, and CAI) -> Master.
Completing the Practice Manager stream only grants one of the three required designations for the Master level.
-
✗ Managing Professional -> Strategic Leader -> Master (Practice Manager is optional).
ITIL 5 clearly states that ITIL Master requires the completion of all three pathways: PM, MP, and SL.
-
-
23 Information Security Management must evaluate an AI solution's 'Risk Governance.' In ITIL 5, what is the specific role of 'Assurance' in this context?
Assurance involves oversight, ethical standards, and accountability for outcomes.
Ensuring that accountability is assigned when an AI model makes a decision and that risks are managed throughout the lifecycle.
Assurance focuses on ethical compliance, oversight, and maintaining trust in automated or complex systems.
-
✗ Building the AI models to ensure they are secure by design.
Building models is a technical/development function; Assurance is about oversight and validation.
-
✗ Marketing the AI solution to customers to ensure they trust the technology.
Marketing is a commercial function; while trust is an outcome of assurance, the practice itself focuses on governance and risk.
-
✗ Running the daily monitoring and event logging for the AI platform.
Monitoring and event logging are operational activities within the MSF bundle, not the primary focus of the CAI's Assurance capability.
-
-
24 Which component of the ITIL 5 Service Value System (SVS) is primarily responsible for ensuring that all Collaborate, Assure and Improve activities remain aligned with organizational goals?
Look for the SVS component that focuses on evaluation, direction, and monitoring.
Governance.
Governance is the component of the SVS that evaluates, directs, and monitors the organization to ensure alignment with strategy.
-
✗ The Guiding Principles.
Guiding principles provide advice for making decisions but are not the formal component responsible for directional alignment and control.
-
✗ Continual Improvement.
Continual improvement optimizes existing work but does not set the initial strategic direction or governance boundaries.
-
✗ The Service Value Chain (Value Chain).
The Value Chain is the operational model for converting demand to value, while Governance provides the oversight for that model.
-
-
25 A manager is leading an 'Internal Improvement or Remediation' transformation for the SLM practice. They discover that $40.0\%$ of existing SLAs are never reviewed. Which Execution Pattern and which CAI practice should be prioritized?
The situation involves a predictable fix for a known internal procedural error.
The Implement Pattern and Continual Improvement.
Because fixing internal process waste (unreviewed SLAs) is a predictable remediation, the Implement Pattern works, supported by the improvement practice.
-
✗ The Implement Pattern and Supplier Management.
This remediation focuses on internal performance targets (SLM), making Supplier Management a secondary concern in this specific scenario.
-
✗ The Discover Pattern and Relationship Management.
Remediating a known internal procedural failure (lack of review) is generally an 'ordered' task rather than an unpredictable 'complex' one.
-
✗ The Contain Pattern and InfoSec.
Unreviewed SLAs are an efficiency problem, not a chaotic crisis or security failure requiring a 'Contain' response.
-
-
26 In ITIL 5, the 'Product and Service Lifecycle' replaces the 'Service Value Chain.' What is a key benefit of this for the CAI practices?
Think about how data from operations reaches the designers in a modern, agile-aligned framework.
It creates a loop-like behavior where data from 'Operate' and 'Support' feeds back into 'Design' and 'Discover' automatically.
This flow-based approach ensures that continual improvement and experience data are integrated into the product's evolution.
-
✗ It eliminates the need for Supplier Management during the 'Discover' phase.
Supplier management is essential during 'Discover' to evaluate potential partners for new products.
-
✗ It mandates that all assurance checks occur only at the 'Transition' stage.
Assurance is embedded throughout the lifecycle to enable 'Shift-Left' and higher velocity with lower risk.
-
✗ It reduces the number of activities from six to four, simplifying the model.
The lifecycle model actually increased the activities to eight (from the previous six in the ITIL 4 value chain) to provide more granularity.
-
-
27 A Practice Manager holding an ITIL 4 Foundation certificate wants to earn the ITIL 5 Practice Manager designation. What is the most cost-effective path according to the 'Transition Tips'?
Consider the validity of prior investments in the previous version's entry-level certification.
They can go straight to the advanced ITIL 5 modules (e.g., CAI and Transformation) without retaking Foundation.
The transition guidance explicitly states that ITIL 4 Foundation holders do not need to retake the entry-level exam for advanced training.
-
✗ They must retake the full ITIL 5 Foundation course and exam first.
ITIL 4 Foundation remains a valid prerequisite for advanced ITIL 5 certifications; retaking it is unnecessary.
-
✗ They must complete the ITIL 4 Managing Professional Transition module first.
The MP Transition is a path for experts, but not a mandatory step for a Foundation holder aiming for the Practice Manager designation.
-
✗ They must earn the ITIL 4 'Create, Deliver and Support' (CDS) certificate to be eligible for ITIL 5 Practice Manager.
In ITIL 5, the CDS requirement has been replaced by the ITIL Transformation (Version 5) module.
-
-
28 Which ITIL 5 concept specifically addresses the human-centric design of services to ensure they provide resilience and sustainable value, aligning with 'Industry 5.0'?
Focus on the competency that emphasizes the user, customer, and employee journey as the core of value.
Digital Experience (DX).
ITIL 5 aligns with Industry 5.0 by prioritizing human-centric design, employee experience, and sustainability within Digital Experience management.
-
✗ The AI Capability Model (6Cs).
The 6Cs model classifies AI functions; while it supports the framework, it is not the primary driver of the Industry 5.0 shift.
-
✗ The Theory of Constraints (ToC).
ToC is a tool for maximizing operational output and flow, not a specific mindset for human-centricity or sustainability.
-
✗ Value Stream Mapping (VSM).
VSM is a technique to visualize work; it is used across both ITIL 4 and ITIL 5 and is not unique to the Industry 5.0 transition.
-
-
29 A supplier consistently fails to meet a 'Warranty' requirement for information security, yet their 'Utility' for the business is extremely high because they own a proprietary technology. How should CAI practices handle this conflict?
Seek a resolution that acknowledges both the functional benefit and the operational risk.
Relationship Management should lobby for an exception, while Supplier Management works with the vendor on a Continual Improvement plan to close the security gap.
This approach balances the business need (RM) with the formal improvement and governance required to mitigate the risk (SM and CI).
-
✗ Terminate the vendor immediately as security (warranty) is non-negotiable.
Termination ignores the 'utility' (functionality) the business depends on; a balanced approach to risk and value is needed.
-
✗ SLM should hide the failure in the quarterly reports to protect the relationship.
Hiding failures is unethical and prevents the organization from managing real business and security risks.
-
✗ InfoSec should take over the vendor's internal operations to fix the security ourselves.
One organization cannot legally or operationally take over another's internal processes without complex legal restructuring.
-
-
30 Within the 'Execution Layer' of a CAI-driven transformation, the team identifies that a partner's security controls are 'Chaotic' following a recent merger. Which action is mandatory according to the ITIL 5 Execution Patterns?
In the face of chaos and high risk, the first priority is stabilization, not experimentation or standard procedures.
Apply the 'Contain' pattern to stabilize immediate failures before attempting long-term systematic change.
The Contain pattern is explicitly required for chaotic, high-risk situations where immediate stabilization is the priority.
-
✗ Conduct an iterative 'Discover' patterns workshop to find new security tools.
Discovery is for complex environments; chaotic environments require immediate stabilization first.
-
✗ Implement the standard 'best practice' security controls from the PIC bundle.
Standard implementation assumes an 'ordered' environment; it will fail in a 'chaotic' context where the current state is not understood.
-
✗ Ignore the chaotic context and focus on the 'Learning Layer' to capture what went wrong.
Ignoring a chaotic crisis to focus on learning ensures that the crisis will worsen; stabilization (Containment) must come first.
-